Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Plugin Vulnerabilities Threaten Websites

WordPress Plugin Vulnerabilities Threaten Websites

Posted on June 3, 2026 By CWS

Hundreds of thousands of websites are currently at risk due to vulnerabilities identified in two popular WordPress plugins, Kirki and Burst Statistics. Security experts at Defiant have raised alarms about these flaws, which could allow attackers to exploit sites using these plugins.

Kirki Plugin Security Flaw

Kirki, known for enhancing WordPress customization and page creation, has been flagged for a critical vulnerability affecting its versions 6.0.0 to 6.0.6. This flaw, tracked as CVE-2026-8206 with a severity score of 9.8, compromises the password reset mechanism. Attackers can manipulate this feature by providing a username and a fabricated email address, receiving a password reset key at the attacker-controlled email.

This security lapse permits attackers to reset the password of a high-privilege account, potentially taking over the entire WordPress site. It highlights a significant risk to site administrators who have not yet updated to the latest plugin version.

Burst Statistics Vulnerability

Burst Statistics, a tool offering analytics insights for WordPress users, is also under scrutiny. Versions 3.4.0 to 3.4.1.1 suffer from an authentication bypass vulnerability. This issue allows unauthorized users to elevate their privileges and assume administrator rights on a compromised site.

The vulnerability arises from a flaw in the validation of application passwords, enabling attackers to exploit the REST API and temporarily impersonate an administrator. The implications include unauthorized access to critical administrative functions, such as creating new admin accounts.

Preventive Measures and Recommendations

Defiant reports blocking thousands of attack attempts targeting these vulnerabilities in just 24 hours. They caution that a significant number of sites remain vulnerable, with Kirki installed on over 500,000 sites and Burst Statistics on more than 200,000.

To safeguard against these threats, users are strongly advised to update their plugins. The latest secure versions are Kirki 6.0.7 and Burst Statistics 3.4.2. These updates contain patches that address the security concerns identified.

In conclusion, staying vigilant and ensuring plugins are updated promptly is crucial in maintaining website security. As cyber threats evolve, proactive measures are essential to protect digital assets from exploitation.

Security Week News Tags:authentication bypass, Burst Statistics, CVE-2026-8206, Cybersecurity, Defiant, Kirki, plugin vulnerabilities, privilege escalation, website security, WordPress

Post navigation

Previous Post: GitHub OAuth Tokens Vulnerable to One-Click Attack
Next Post: Ivanti ITSM Vulnerability Risks Admin Access

Related Posts

North Korean Hackers Steal 5M from DeFi Platform North Korean Hackers Steal $285M from DeFi Platform Security Week News
CareCloud Investigates Possible Cybersecurity Breach CareCloud Investigates Possible Cybersecurity Breach Security Week News
Chinese Cybersecurity Firm’s AI Claims Rival Top Models Chinese Cybersecurity Firm’s AI Claims Rival Top Models Security Week News
US Braces for Cyberattacks After Joining Israel-Iran War US Braces for Cyberattacks After Joining Israel-Iran War Security Week News
Hunters International Shuts Down, Offers Free Decryptors as It Morphs Into World Leaks Hunters International Shuts Down, Offers Free Decryptors as It Morphs Into World Leaks Security Week News
Hundreds of Salesforce Customers Hit by Widespread Data Theft Campaign Hundreds of Salesforce Customers Hit by Widespread Data Theft Campaign Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Linux Kernel Vulnerability Exploitation Alert
  • Minecraft Malware Spread through YouTube and SEO Tactics
  • Cyber Attack Exposes Global Stock Exchange Data
  • Understand Your Network from an Attacker’s Viewpoint
  • Critical CRLF Vulnerability in Laravel Threatens Email Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Linux Kernel Vulnerability Exploitation Alert
  • Minecraft Malware Spread through YouTube and SEO Tactics
  • Cyber Attack Exposes Global Stock Exchange Data
  • Understand Your Network from an Attacker’s Viewpoint
  • Critical CRLF Vulnerability in Laravel Threatens Email Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark